ZLysander
Login Sign Up

Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Data Sharing
  6. International Transfers
  7. Data Retention
  8. Your Rights
  9. Cookies
  10. Children's Privacy
  11. Changes to This Policy
  12. Contact Us

Privacy Policy

Last updated: 18 June 2026  ·  Effective: 18 June 2026

This Privacy Policy explains how Haijahr Ltd ("Haijahr", "we", "us", or "our") collects, uses, stores, and protects personal data when you use Lysander — our practice management platform for counsellors, coaches, and therapy practitioners.

We are committed to protecting your personal data and complying with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR).


1. Who We Are

The data controller for Lysander is:

Haijahr Ltd
61 Alexandra Road
Lowestoft, Suffolk
NR32 1PL
United Kingdom

Website: haijahr.com
Email: privacy@haijahr.com

Haijahr Ltd is registered with the Information Commissioner's Office (ICO) as a data controller. We are also the developer of Brefi, a separate product governed by its own privacy policy.

2. Data We Collect

2.1 Account and Registration Data

When you create a Lysander account we collect:

  • Full name
  • Email address
  • Password (stored as a one-way cryptographic hash — never in plain text)
  • Your professional role (Counsellor or Business Admin)
  • Organisation name (if you create or join a practice organisation)

2.2 Patient Records

Lysander allows authorised counsellors to record information about their patients. This may include:

  • Patient name, email address, date of birth, and phone number
  • Session notes and clinical observations
  • Task descriptions and assignment files
  • Files uploaded by patients through their personal portal

Counsellors act as independent data controllers for their patient records. Haijahr acts as a data processor in respect of patient data and processes it solely on the instructions of the counsellor. You should ensure your patients are informed of this under your own professional privacy obligations.

2.3 Usage and Technical Data

We automatically collect certain technical data when you use Lysander, including:

  • IP address and browser type
  • Pages visited and features used
  • Date and time of access
  • Session identifiers stored in cookies

2.4 Communications

If you contact us by email or through our website, we retain a record of that correspondence including your contact details and the content of your message.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Providing the Lysander service — creating and managing your account, processing logins, and delivering the features you use
  • Invitations and team management — sending invitation emails when a Business Admin invites a counsellor to their organisation
  • Service communications — sending essential notices about your account, security alerts, or significant changes to the service
  • Customer support — responding to your queries and resolving issues
  • Security and fraud prevention — monitoring for abuse, unauthorised access, and maintaining the integrity of the platform
  • Legal compliance — meeting our obligations under applicable law
  • Service improvement — understanding how Lysander is used in aggregate to improve features and performance (using anonymised or pseudonymised data wherever possible)

We do not use your data for advertising, sell it to third parties, or use it to profile you for marketing purposes.

4. Legal Basis for Processing

Under UK GDPR, we rely on the following legal bases:

PurposeLegal Basis
Providing and managing your accountPerformance of a contract (Article 6(1)(b))
Sending invitation emailsLegitimate interests (Article 6(1)(f)) — facilitating team collaboration you requested
Essential service communicationsLegitimate interests (Article 6(1)(f)) — keeping you informed about your account
Security and fraud preventionLegitimate interests (Article 6(1)(f)) — protecting users and the platform
Legal obligationsLegal obligation (Article 6(1)(c))
Analytics cookies (if consented)Consent (Article 6(1)(a))
Processing patient records on behalf of counsellorsWe act as a data processor; the counsellor is the data controller and must establish their own legal basis

Where we rely on legitimate interests, we have balanced our interests against your rights and concluded that our processing does not override your fundamental rights and freedoms.

5. Data Sharing

We do not sell your personal data. We may share it with:

  • Hosting and infrastructure providers — the servers that power Lysander. All providers are vetted and subject to data processing agreements.
  • Email delivery services — used to send transactional emails such as invitation links. Only the recipient's email address and message content are shared.
  • Professional advisers — lawyers, accountants, and auditors who are bound by professional confidentiality obligations.
  • Law enforcement or regulators — where we are legally required to do so.

We require all third-party processors to handle your data securely and in compliance with UK GDPR. A current list of the sub-processors that may process patient data on our behalf — with their purpose and location — is published on our Sub-processors page.

6. International Transfers

We aim to store and process your data within the United Kingdom or the European Economic Area (EEA). If any transfer outside these areas is necessary — for example, by a cloud infrastructure provider — we ensure it is protected by appropriate safeguards, such as the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs), in accordance with UK GDPR Chapter V.

7. Data Retention

We retain your personal data only for as long as necessary:

  • Account data — retained for the duration of your account plus up to 3 years after account closure, to comply with legal and accounting obligations
  • Patient records — retained as directed by the counsellor who controls them; counsellors are responsible for ensuring their own retention obligations are met
  • Uploaded files — deleted when the associated record is deleted or when the account is closed
  • Usage and technical logs — retained for up to 12 months for security purposes
  • Support correspondence — retained for up to 3 years after the last contact

When data is no longer needed, it is securely deleted or anonymised.

8. Your Rights

Under UK GDPR, you have the following rights regarding your personal data:

  • Right of access — you may request a copy of the personal data we hold about you
  • Right to rectification — you may ask us to correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") — you may ask us to delete your data where there is no overriding legal reason to retain it
  • Right to restriction — you may ask us to restrict processing in certain circumstances
  • Right to data portability — you may request your data in a structured, machine-readable format
  • Right to object — you may object to processing based on legitimate interests
  • Rights related to automated decision-making — Lysander does not make solely automated decisions that produce legal or similarly significant effects
  • Right to withdraw consent — where processing is based on consent (e.g. analytics cookies), you may withdraw it at any time via the cookie preferences link in the footer

To exercise any of these rights, please contact us at privacy@haijahr.com. We will respond within one calendar month of receiving your request.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire, SK9 5AF
Tel: 0303 123 1113
ico.org.uk

9. Cookies

Lysander uses cookies to operate the service. For full details of the cookies we use and how to manage them, please read our Cookie Policy.

10. Children's Privacy

Lysander is intended for use by professional practitioners and is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If you believe we have inadvertently collected such data, please contact us immediately at privacy@haijahr.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or by displaying a prominent notice within Lysander before the changes take effect. The "Last updated" date at the top of this page will always reflect the most recent revision.

Continued use of Lysander after the effective date constitutes acceptance of the revised policy.

12. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:

Data Protection Enquiries
Haijahr Ltd
61 Alexandra Road, Lowestoft, Suffolk, NR32 1PL
Email: privacy@haijahr.com
Website: haijahr.com
Terms & Conditions Cookie Policy
© 2026 Haijahr Ltd. All rights reserved.
Privacy Policy Terms & Conditions Cookie Policy Data Processing Sub-processors Disclaimer Accessibility SLA

🍪 We use cookies

We use essential cookies to keep the site working and optional cookies to improve your experience. By clicking Accept All you consent to all cookies. Privacy Policy · Cookie Policy

Cookie Preferences

Strictly Necessary Always On

Required for the site to function. Includes your session, security token, and login state. These cannot be disabled.

Functional

Remembers your preferences such as "Remember me" on login. Disabling this means you will need to log in each visit.

Analytics & Performance

Helps us understand how visitors use Lysander so we can improve the service. No personal data is shared with third parties.